technical-artist

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the dynamic context injection syntax (!cat ...) to execute shell commands at load time. These commands are used to populate the agent's context with various protocol and configuration files (e.g., game-visual-foundations.md, ux-protocol.md, .production-grade.yaml).
  • Evidence: Multiple !cat commands are present in the Protocols and Engagement Mode sections of SKILL.md to aggregate context from local files.
  • [PROMPT_INJECTION]: The use of dynamic context injection creates a surface for indirect prompt injection. External content is ingested directly into the system prompt without boundary markers or sanitization, meaning the agent could be influenced by instructions embedded in those files.
  • Ingestion points: SKILL.md ingests content from multiple paths including skills/_shared/protocols/, .production-grade.yaml, and .forgewright/settings.md.
  • Boundary markers: Absent. The content of the cat-ed files is merged directly into the agent's prompt context without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill is designed for technical art documentation and specification; it does not explicitly invoke high-risk tools such as network-send, file-write, or privilege escalation commands.
  • Sanitization: Absent. The ingested file content is not escaped or validated before being added to the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — technical-artist